Privacy & data policy

What we read, store, and never touch.

Throttle is local-first. Cloud sync via the tokenmaxx backend is optional and only activates when the extension is explicitly paired. Numeric usage only — never prompt or chat content.

1. What the extension reads

The numeric quota indicators rendered by Claude and Lovable in their own UI: percentages, counters, reset timestamps, plan identifier when present.

2. What the extension never reads

Prompt content, chat content, generated code, project files, page or DOM text outside the quota surface. The extension does not exfiltrate, transcribe, or summarize anything you write or anything any model writes back.

3. What stays local

By default, everything. Snapshots are written to the extension's local IndexedDB store. The extension is fully functional without an account.

4. What goes to the backend when sync is enabled

Numeric snapshots tagged with a provider identifier (e.g. account email visible to the provider), the timestamp, and the plan label. No content. Sync only activates after explicit pairing.

5. How to delete cloud data

From the dashboard, use Data Controls → Delete cloud snapshots. The deletion is immediate and irreversible.

6. How to revoke an API key

From the dashboard, use Access → Revoke. The extension will fall back to local-only immediately.

7. What the research dataset includes and excludes

Includes: anonymized aggregate quota patterns from accounts that have explicitly opted in. Excludes: any per-user identifier, any content, any company-attributable information. Research contribution is OFF by default.

8. Outreach policy

Creating an account does not opt you into sales outreach. Research contribution is separate and explicit. Account-holder contact information is not used for marketing.